Secrover
Open-source tool to generate professional HTML security audit reports
252 stars 3 forks last commit first released GPL-3.0
Actively maintained
Last commit 19 Aug 2026.

Secrover is a free, open-source tool that automates generation of clear, professional HTML security audit reports for code repositories and domains. It combines dependency scanning, static code checks, and domain/SSL checks into a single shareable report.
Key Features
- Dependency vulnerability scanning using OSV-based scanners to report known issues across supported languages
- Static code checks via integrated search tools to surface potentially risky code patterns
- Domain and hosting audits: SSL/TLS, redirects, security headers, open ports, and basic hosting location info
- Produces standalone human-readable HTML reports suitable for stakeholders and public sharing
- Automation support: run one-off scans via Docker or schedule recurring scans using an internal cron (Supercronic)
- Remote export options for reports using rclone-compatible destinations (S3, SFTP, WebDAV, SMB, Google Drive)
- Support for private GitHub repositories via HTTPS Personal Access Token
Use Cases
- Generating repeatable security audit reports for open-source projects or internal repositories
- Producing client-facing or compliance-ready HTML reports after dependency and code scans
- Integrating scheduled security scans into CI workflows and exporting results to cloud storage or intranet sites
Limitations and Considerations
- Private repository cloning currently works only over HTTPS with a GitHub Personal Access Token; SSH is not supported
- Dependency scanning and language coverage depend on the capabilities of the integrated external scanners (e.g., OSV scanner)
- Scans of very large repositories or many targets may be resource- and time-intensive when run in single-container setups
Secrover is a practical choice when you need transparent, shareable security audit reports without a proprietary SaaS dependency. It is designed for simple Docker-based deployment, automation via cron or CI, and flexible export destinations for report distribution.
Categories:
Tags:
Tech Stack:
Similar to Secrover
RunsOn
Self-hosted GitHub Actions runners on AWS EC2
RunsOn deploys scalable, ephemeral GitHub Actions runners in your AWS account with spot/on-demand support, integrated S3-backed caching, and workflow compatibility.

PruneMate
Flask-based web UI for scheduled Docker resource cleanup
Lightweight Flask web UI to schedule, preview and run Docker prune operations across single or multiple hosts, with reporting and notifications.

RapidForge
Single-binary platform for internal tools, webhooks, APIs and scheduled scripts
Single-binary platform that turns Bash/Lua scripts into HTTP endpoints, webhooks, cron jobs and visual pages with built-in auth, OAuth and credential management.

Boxarr
Automated box office tracker that integrates with Radarr
Tracks weekly box office charts and automatically adds trending theatrical releases to Radarr with filters, scheduling, and a web dashboard.
Taskwarrior
Command-line task management utility for todo lists and workflows
Open-source CLI task manager with tagging, projects, priorities, recurrence, filtering, extensible hooks and optional sync.

OpenEMR
Open-source EHR and medical practice management system
OpenEMR is an open-source electronic health records (EHR/EMR) and practice management platform for clinics, including scheduling, billing, and interoperability features.





